Sceawere

Vulnerability Detail

CVE-2026-104419UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Zebrad Peer Misbehavior Denial-of-Service

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.8
Creation Date
11h ago
Vendor
ZcashFoundation
Product
zebra
Attack Type
Insufficient Verification of Data Authenticity
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:L
Attack Complexity
HIGH

Narrative and Response

Description

Zebra (zebrad) 4.5.0 before 6.3.0 discards which peer supplied the block hashes in FindBlocks responses, then assigns 100 misbehavior points, the ban threshold, to whichever peer serves a requested block more than 50,000 heights above the tip. A remote peer can return real far-ahead hashes to a syncing node so that honest peers get banned, eroding its peer set and raising eclipse risk.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.8",
  "pubDate": "2026-10-02T12:17:11.850Z",
  "pubdate": "2026-10-02T12:17:11.850Z",
  "executiveSummary": "This vulnerability in Zebrad (versions 4.5.0 through 6.2.x) concerns an improper peer reputation management mechanism during block synchronization. The software fails to correctly attribute the source of provided block hashes in FindBlocks responses, resulting in the misattribution of penalties.\nSpecifically, when the node receives a block response that exceeds the 50,000-height threshold relative to the current chain tip, it automatically assigns 100 misbehavior points to the peer providing the data. Because the system fails to correctly associate these hashes with the specific remote peer, the application erroneously applies the penalty to an incorrect peer identity.\nThis flaw can be weaponized by a malicious remote peer to cause an eclipse attack or network partition by forcing the node to systematically ban honest, legitimate peers. By crafting responses containing far-ahead hashes, an attacker can induce a denial-of-service condition where the target node depletes its peer set, effectively isolating it from the network and preventing legitimate synchronization and transaction propagation. No authentication is required for remote peers to trigger this behavior, and the attack requires only standard network connectivity to the node's P2P interface.",
  "technicalDetails": "The vulnerability resides within the peer-to-peer synchronization logic of zebrad, specifically in how the node processes and validates responses to 'FindBlocks' requests. When a syncing node requests block hashes from its peers, it expects responses that align with its current understanding of the chain tip.\nThe root cause of this vulnerability is a state-tracking failure: zebrad fails to maintain a binding between a specific FindBlocks request and the responding peer. Consequently, when a response is received containing block hashes, the validation logic determines if the hashes are 'too far ahead' (defined as > 50,000 blocks above the current chain tip).\nUnder normal operating conditions, if a peer sends data that deviates significantly from the expected state, it is penalized. In this vulnerable implementation, when the 50,000-height threshold is breached, the node triggers a misbehavior penalty of 100 points, which is the defined ban threshold for zebrad. Because the system cannot track which peer originally provided the malformed or outlier data, it applies these points incorrectly, potentially targeting honest peers that provided valid responses to other pending requests.\nThe attack flow proceeds as follows: 1) An attacker connects to the target zebrad node as a remote peer. 2) The attacker waits for the target to initiate a synchronization process, resulting in the node sending a FindBlocks request. 3) The attacker responds with a carefully crafted payload containing block hashes that are significantly ahead of the current chain tip. 4) The zebrad node identifies the 'far-ahead' condition and invokes the penalty function. 5) Due to the lack of correct association, the 100-point penalty is assigned to the wrong peer in the node's peer set, leading to the immediate disconnection and blacklisting of that victim peer.\nThis exploitation strategy allows an attacker to repeatedly trigger bans against innocent nodes. By continuously providing malicious hashes, an attacker can systematically erode the target's peer set until the target is completely eclipsed. The impact is significant, as it prevents the node from participating in consensus, verifying the ledger, and effectively renders the node unable to propagate transactions or blocks. The vulnerability is present in versions 4.5.0 up to 6.3.0 and does not require elevated privileges or pre-existing trust, as it leverages the standard P2P messaging protocol."
}
CVE-2026-104419: Zebrad Peer Misbehavior Denial-of-Service (MEDIUM Severity, CVSS: 4.8) | Sceawere